Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,389 rules
Suspicious Scheduled Task with NetworkProfile Event Trigger (via process_creation)
This rule detects schtasks creating a task triggered on Microsoft-Windows-NetworkProfile operational events. The PHANTOM#SPIKE campaign used this uncommon event based trigger to persistently launch a custom CSharp backdoor.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-06-23Malicious Credential Dumping via XenAllPasswordPro
This rule detects execution of the XenAllPasswordPro password recovery utility. The Crypt Ghouls group ran this tool to harvest stored credentials into an HTML report during their intrusions, and its presence on endpoints is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh249Premium2026-06-23Renamed Grandoreiro DLL Sideloading via mingwm10 from User-Writable Path (via image_load)
This rule detects a process loading a mingwm10 runtime DLL from a user-writable directory, the side-loading vehicle used by the Grandoreiro banking trojan in its Brazil-to-Mexico campaign where a renamed Duplicate Files Finder binary loads a malicious mingwm10 DLL. Adversaries drop the trojanized runtime beside a relocated legitimate binary to execute under a trusted process. Loads from download or temp paths rather than an install directory are anomalous.
HuntRule TeamWindowsimage_loadLow121Premium2026-06-23Suspicious Reactivation of Guest Account via net user (UAT-8099)
This rule detects reactivation of the built-in Guest account using net user guest with the active flag. UAT-8099 re-enables and elevates the Guest account to maintain covert administrative access to compromised IIS servers. Enabling the normally disabled Guest account is an account-manipulation persistence technique.
HuntRule TeamWindowsprocess_creationHigh327Premium2026-06-23Malicious Scheduled Task EPolicyManager by Squidoor (via process_creation)
This rule detects creation of the scheduled task Microsoft\Windows\AppID\EPolicyManager used by the Squidoor backdoor to persist by mimicking a legitimate Windows AppID task. Registering persistence under a trusted-looking task path helps the actor survive reboots while avoiding operator suspicion.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-06-23Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
This rule detects execution of a binary named My Pictures.exe which VenomRAT copies onto removable drives to spread across hosts in the RevengeHotels campaign. The lure name mimics a familiar folder to trick users into launching it from a USB device. An executable using this decoy name is indicative of USB-based propagation.
HuntRule TeamWindowsprocess_creationMedium257Premium2026-06-23Malicious NTDS Credential Theft via Volume Shadow Copy via process_creation
This rule detects volume shadow copy creation with vssadmin or direct references to the ntds.dit Active Directory database used to steal domain credentials. Stately Taurus used vssadmin and NTDS.dit access on a compromised domain controller to harvest the credential store, a high-confidence sign of domain-wide credential access.
HuntRule TeamWindowsprocess_creationHigh261Premium2026-06-23Suspicious Run Key Persistence Launching Headless Deno Runtime via TAG-150
This rule detects a Run key persistence value that launches the Deno runtime through a headless conhost wrapper. TAG-150 uses this technique across its DinDoor, DenoRAT, and NightshadeC2 tooling to silently reload JavaScript backdoors at logon. The headless conhost prefix suppresses the console window while maintaining autostart command and control.
HuntRule TeamWindowsregistry_setHigh172Premium2026-06-22Suspicious Data Exfiltration to Anonymous File Sharing Services (via dns_query)
This rule detects DNS lookups for the anonfiles and bayfiles anonymous file sharing services, which the Cyclops stealer uses to upload harvested victim data over web services. Exfiltration to anonymous upload endpoints lets the attacker collect stolen credentials and documents while evading corporate data controls.
HuntRule TeamWindowsdns_queryMedium298Premium2026-06-22Suspicious CMD Script Dropped in Startup Folder for Persistence
This rule detects creation of a .cmd batch file inside the user Startup folder. The Lampion loader plants a command script in the Startup directory so it runs automatically at each logon. Batch scripts appearing in the Startup folder are an uncommon and high-value persistence indicator.
HuntRule TeamWindowsfile_eventMedium423Premium2026-06-22Masquerading Blank Grabber Payload Decoding via Certutil Decode Flag (via process_creation)
This rule detects certutil being run with its decode flag to convert a base64-encoded file back into an executable payload, the deobfuscation step Blank Grabber uses to reconstruct its loader while masquerading the data as a certificate. Adversaries leverage certutil as a trusted LOLBin to decode staged payloads and evade content controls, making early detection critical for catching the loader before execution.
HuntRule TeamWindowsprocess_creationHigh156Premium2026-06-22Malicious Named Pipe REDSUN Created by Nightmare-Eclipse Tooling
This rule detects creation of a named pipe called REDSUN, a hardcoded inter-process channel used by Nightmare-Eclipse tooling observed in a real-world Huntress intrusion. The agent relies on this fixed pipe name for command relay between its components. Because the pipe name is a distinctive tool-specific constant, its presence is a high-confidence indicator of the framework.
HuntRule TeamWindowspipe_createdHigh93Premium2026-06-22Malicious Windows Defender Real-Time Monitoring Disabled via PowerShell
This rule detects use of Set-MpPreference to disable Windows Defender real-time monitoring. In the WithSecure Catching Lazarus research the actor turns off real-time protection before dropping and running further tooling. Attackers disable defensive agents to run payloads without antivirus detection.
HuntRule TeamWindowsprocess_creationHigh157Premium2026-06-22Suspicious PowerShell Download From catbox.moe (via process_creation)
This rule detects PowerShell referencing the catbox.moe file-sharing service, abused in the Cascading Shadows campaign to deliver later stages of a multi-step loader chain. Retrieving payloads from this public host lets the attacker stage malware while blending with legitimate file-sharing traffic.
HuntRule TeamWindowsprocess_creationMedium311Premium2026-06-22Suspicious Hidden PowerShell Retrieving VBScript from mcdir.me by Millenium RAT (via process_creation)
This rule detects hidden PowerShell fetching a VBScript stager from the mcdir.me delivery host used in the Millenium RAT malware-as-a-service infection chain launched from a malicious LNK. The script downloads and runs the next-stage executable while showing the victim a decoy PDF. Detecting the download cradle interrupts the RAT installation early.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-06-22